Sygnia says China-nexus group Velvet Ant spent nearly a decade hiding inside Linux login components, backdooring PAM and OpenSSH to steal credentials and maintain access on isolated networks. The campaign, called Operation Highland, shows how tampering with trusted infrastructure can evade normal cleanup and why defenders must verify critical system files. #VelvetAnt #Sygnia #PAM #OpenSSH #OperationHighland
Keypoints
- Velvet Ant hid inside Linux PAM and OpenSSH components instead of using obvious malware.
- The group has been active since at least 2016 and targeted isolated networks with no direct internet access.
- Backdoored login modules were used to grant access, steal credentials, and log commands.
- The attacker used internet-facing systems as bridges to reach internal segments.
- Defenders must verify trusted binaries, monitor changes, and remove backdoors before resetting passwords.
Read More: https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html